projectmanagement

Warn

Audited by Socket on Mar 24, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
miniproject/SKILL.md

SUSPICIOUS: mostly coherent as a local markdown project-management skill, but it has two notable trust expansions: an unseen local helper script at a fixed absolute path and a transitive brave_search dependency for research. The main security concern is indirect prompt injection from external research content combined with write/command capabilities, not overt malware or credential theft.

Confidence: 82%Severity: 56%
AnomalyLOW
ralph-loop/SKILL.md

SUSPICIOUS: the skill’s behavior is mostly coherent for iterative loop orchestration and local task tracking, with no clear credential theft or exfiltration. However, install provenance is weak because web evidence shows fragmented third-party distribution and registry-based skill installation paths, and the subagent loop design increases autonomous-action and prompt-injection exposure.

Confidence: 84%Severity: 56%
AnomalyLOW
jira/SKILL.md

SUSPICIOUS: The skill’s Jira-focused capabilities are broadly aligned with its stated purpose, but it routes sensitive Atlassian operations through a non-Atlassian third-party CLI (`mcporter`). That makes the install/execution trust and credential-forwarding posture weaker than an official Atlassian client path. No clear malicious exfiltration or unrelated capability is shown, but the third-party client in the auth path raises medium security concern.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 24, 2026, 03:24 AM
Package URL
pkg:socket/skills-sh/zenobi-us%2Fdotfiles%2Fprojectmanagement%2F@aa011f059f839ce4601106568450e5693596febd